In the previous article --- Account Lockout (part 1 of 4), I ever enable NETLOGON record function by the command “
nltest /dbflag:0x2080ffff” so that its behavior will be recorded on
C:\Windows\Debug\netlogon.log
data:image/s3,"s3://crabby-images/51d14/51d14b8a750015f697c226b96c5e94ab76d5e08d" alt="ScreenHunter_03 Jun. 29 13.38 ScreenHunter_03 Jun. 29 13.38"
Or add registry entity
DBFlag on “
HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters”
data:image/s3,"s3://crabby-images/6b1a8/6b1a8cf85d607efd60091627ee921b4ea57ee1bf" alt="ScreenHunter_23 Jun. 28 18.14 ScreenHunter_23 Jun. 28 18.14"
In the moment, I will use nlparse.exe this utility to analyze netlogon.log
Open nlparse.exe by
Run as administrator data:image/s3,"s3://crabby-images/8f370/8f370f44dbf319aebbcfabd883ceb61acc4208ba" alt="ScreenHunter_01 Jul. 12 12.06 ScreenHunter_01 Jul. 12 12.06"
The error message will show up and tell us that component ‘comdlg32.ocx’ or one of its dependencies not correctly registered.
data:image/s3,"s3://crabby-images/73cdc/73cdc5feef3231549422d6d9419a795c6abd8017" alt="ScreenHunter_02 Jul. 12 12.06 ScreenHunter_02 Jul. 12 12.06"
Search the related information about this error message by Google and find we can directly download VB6 Common Control
comdlg32.ocx from this URL
http://activex.microsoft.com/controls/vb6/comdlg32.CAB
After download finish, double-click
comdlg32.CAB this file next to copy comdlg32.ocx to
C:\Windows\SysWOW64\data:image/s3,"s3://crabby-images/6bc34/6bc348b6f67e7d810fdff6b284f0202ba290f76b" alt="ScreenHunter_03 Jul. 12 13.52 ScreenHunter_03 Jul. 12 13.52"
Open command prompt by
Run as Administrator, execute “
regsvr32 c:\Windows\SysWOW64\comdlg32.ocx” to register cmdlg32.
data:image/s3,"s3://crabby-images/5eba6/5eba6f10bed56ac26b8419b57b8fc1835b9b3bf3" alt="ScreenHunter_04 Jul. 12 14.17 ScreenHunter_04 Jul. 12 14.17"
If it success, please run
nlparse.exe again so that Netlogon-Parse GUI will show up normally now.
data:image/s3,"s3://crabby-images/5e42a/5e42a0cbb3d5f0810b47b76f6f33fb5f5d0add84" alt="ScreenHunter_05 Jul. 12 14.21 ScreenHunter_05 Jul. 12 14.21"
Click
Open button
data:image/s3,"s3://crabby-images/d17c1/d17c18d31360bb586856f15eb07b47f0ac9371b4" alt="ScreenHunter_06 Jul. 12 14.23 ScreenHunter_06 Jul. 12 14.23"
Expand
C:\Windows\debug folder and select
netlogon.log this file next to click
Open button
data:image/s3,"s3://crabby-images/1f235/1f235deb7ad784bc77346a1c6657fb17450828f6" alt="ScreenHunter_07 Jul. 12 14.24 ScreenHunter_07 Jul. 12 14.24"
Enable
0xC000006A (no any record if authentication is Kerberos) and
0xC0000234 check box next to click
Open button
data:image/s3,"s3://crabby-images/853bd/853bd6d819b3ffc20d61715ebfd954aeb885c5cf" alt="ScreenHunter_08 Jul. 12 14.25 ScreenHunter_08 Jul. 12 14.25"
You will see the message as “C:\Windows\debug\netlogon.log Done!”
data:image/s3,"s3://crabby-images/45418/454180d15f834e0861ca16e43015bb1da3451304" alt="ScreenHunter_09 Jul. 12 14.25 ScreenHunter_09 Jul. 12 14.25"
Under this folder
C:\Windows\debug, there are generated two file with extension format as txt and csv.
data:image/s3,"s3://crabby-images/83266/8326639069ba714ca45c24bf111ed9e4f20bf053" alt="ScreenHunter_11 Jul. 12 14.27 ScreenHunter_11 Jul. 12 14.27"
Now you can open these file to realize who is locked by which computer.
Reference:
(1).
Support Statement for Visual Basic 6.0 on Windows Vista, Windows Server 2008, Windows 7, and Windows 8
(2). If O.S. is 32bit, please copy comdlg32.ocx to
C:\Windows\System32\(3). If the debug finish, please remember to disable NETLOGON record by command “
nltest /dbflag:0x0” and restart netlogon service so that avoid the disk space overload.
<<<
Account Lockout (part 3 of 4)
沒有留言:
張貼留言